logo

Hackers Abuse Google Ads to Steal Users GoDaddy ManageWP login Credentials

ID: 4c9d8e1a-6e6e-5454-86c8-b67492210f68

STIX ID: report--4c9d8e1a-6e6e-5454-86c8-b67492210f68

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-05-07

Date Updated: 2026-05-08

Author: Tushar Subhra Dutta

...
...

Researchers uncovered the 'WrongPress' campaign in which attackers abuse Google Ads and cloaking to place a fake ManageWP login above the legitimate search result; victims who enter credentials (and 2FA codes) are relayed in real time through an AiTM proxy to the attackers and exfiltrated to a Telegram channel. Guardio Labs confirmed ~200 victims and accessed the operators' C2; because ManageWP accounts can control hundreds of WordPress sites, the campaign poses a high-impact risk. Recommended mitigations include avoiding sponsored search results for logins, bookmarking official URLs, monitoring for unexpected logins, and using phishing-resistant authentication (e.g., hardware keys).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.